pull: Verify SSL/TLS certificates against system CA file by default
authorColin Walters <walters@verbum.org>
Tue, 9 Jul 2013 19:02:48 +0000 (15:02 -0400)
committerColin Walters <walters@verbum.org>
Tue, 9 Jul 2013 19:02:48 +0000 (15:02 -0400)
We also need a mechanism like GIT_SSL_NO_VERIFY...probably an option
in the config.

src/ostree/ostree-fetcher.c

index 045ff3f7738adc8d78161dbc6d819a1932d82b1c..f55b31835db067f590ba6b6b1b54bd4e33de2b6a 100644 (file)
@@ -135,6 +135,7 @@ static void
 ostree_fetcher_init (OstreeFetcher *self)
 {
   self->session = soup_session_async_new_with_options (SOUP_SESSION_USER_AGENT, "ostree ",
+                                                       SOUP_SESSION_SSL_USE_SYSTEM_CA_FILE, TRUE,
                                                        SOUP_SESSION_USE_THREAD_CONTEXT, TRUE,
                                                        SOUP_SESSION_ADD_FEATURE_BY_TYPE, SOUP_TYPE_REQUESTER,
                                                        NULL);